Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
talend vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2022-29942
Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perform SSRF HTTP GET requests on URLs in the internal network. The issue is fixed for versions 8.0.x in TPS-5189, versions 7.3.x in TPS...
Talend Administration Center 8.0.0
Talend Administration Center 7.2.0
Talend Administration Center 7.3.0
6.5
CVSSv3
CVE-2022-29943
Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access as root on the remote filesystem. The issue is fixed for versions 8.0.x in TPS-5189, versions 7.3.x in TPS-5175, and versions 7.2....
Talend Administration Center 8.0.0
Talend Administration Center 7.2.0
Talend Administration Center 7.3.0
6.1
CVSSv3
CVE-2022-31648
Talend Administration Center is vulnerable to a reflected Cross-Site Scripting (XSS) issue in the SSO login endpoint. The issue is fixed for versions 8.0.x in TPS-5233, for versions 7.3.x in TPS-5324, and for versions 7.2.x in TPS-5235. Earlier versions of Talend Administration C...
Talend Administration Center 8.0.0
Talend Administration Center 7.2.0
Talend Administration Center 7.3.0
9.8
CVSSv3
CVE-2014-2228
The XStream extension in HP Fortify SCA prior to 2.2 RC3 allows remote malicious users to execute arbitrary code via unsafe deserialization of XML messages.
Talend Restlet
Talend Restlet 2.2
7.5
CVSSv3
CVE-2023-31444
In Talend Studio prior to 7.3.1-R2022-10 and 8.x prior to 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge.
Talend Studio
5.5
CVSSv3
CVE-2023-26263
All versions of Talend Data Catalog prior to 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting server.
Talend Data Catalog
5.5
CVSSv3
CVE-2023-26264
All versions of Talend Data Catalog prior to 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.
Talend Data Catalog
9.1
CVSSv3
CVE-2021-40684
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or...
Talend Esb Runtime
9.8
CVSSv3
CVE-2021-42837
An issue exists in Talend Data Catalog prior to 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username with an arbitrary password, and login will succeed...
Talend Data Catalog
9.8
CVSSv3
CVE-2021-4311
A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31d442b9fb1d518128fd18f6e4d54e06c3d67793. I...
Talend Open Studio
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »